{"id":2596,"date":"2016-08-10T10:32:36","date_gmt":"2016-08-09T22:32:36","guid":{"rendered":"http:\/\/www.zoyinc.com\/?p=2596"},"modified":"2018-07-15T08:45:24","modified_gmt":"2018-07-14T20:45:24","slug":"public-facing-web-server-on-sonicwall-vlan","status":"publish","type":"post","link":"http:\/\/www.zoyinc.com\/?p=2596","title":{"rendered":"Public facing web server on SonicWALL VLAN"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2600\" src=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWALLWebServer01.jpg\" alt=\"\" width=\"364\" height=\"131\" srcset=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWALLWebServer01.jpg 364w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWALLWebServer01-150x54.jpg 150w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWALLWebServer01-300x108.jpg 300w\" sizes=\"auto, (max-width: 364px) 100vw, 364px\" \/>\u00a0I have a SonicWALL TZ 205w sitting behind my fibre connection with my web server running on an ESXi server connected to the SonicWALL via a VLAN to isolate it from my LAN.<\/p>\n<p>This has proved to be a bit of a mission because I don&#8217;t have a modem between the SonicWALL and the ONT, optical network terminal. In addition my ISP uses a VLAN for fibre. Lastly because my ESX box only has one network card I am using a VLAN for connecting my web server to the SonicWALL.<\/p>\n<h2>Related posts<\/h2>\n<p><a  href=\"http:\/\/www.zoyinc.com\/?p=2582\">ESX VLAN to SonicWALL DMZ<\/a><br \/>\nThis details how to connect an ESX virtual machine to a SonicWALL DMZ to isolate it from the LAN<\/p>\n<p><a  href=\"http:\/\/www.zoyinc.com\/?p=2541\">Connect SonicWALL TZ205w to Fibre ONT<\/a><br \/>\nThis details how to get the SonicWALL connected to fibre with Spark NZ which uses a VLAN.<\/p>\n<h2>Setup<\/h2>\n<p>As with the other related posts it is important to remember I did this with a generation 5 SonicWALL appliance, TZ205w running firmware SonicOS Enhanced 5.9.1.6-5o.<\/p>\n<p>Most of the work for this is done using a wizard, so go click on &#8220;Wizards&#8221; at the top right of the SonicWALL web page<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2603\" src=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/WALLWizardHTTP07.jpg\" alt=\"\" width=\"274\" height=\"111\" srcset=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/WALLWizardHTTP07.jpg 274w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/WALLWizardHTTP07-150x61.jpg 150w\" sizes=\"auto, (max-width: 274px) 100vw, 274px\" \/><\/p>\n<p>Select &#8220;Public Server Wizard&#8221; and click on &#8220;Next&gt;&#8221;<\/p>\n<p>On the &#8220;Public Server Type&#8221; select &#8220;Web Server&#8221; and enable only HTTP. I find it easier to do this as two tasks. Click on &#8220;Next&gt;&#8221; to continue.<\/p>\n<p>On the &#8220;Server Private Network Configuration&#8221; page enter a server name the internal details of the internal web server:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-3152\" src=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer01.jpg\" alt=\"\" width=\"450\" height=\"305\" srcset=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer01.jpg 450w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer01-150x102.jpg 150w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer01-300x203.jpg 300w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer01-443x300.jpg 443w\" sizes=\"auto, (max-width: 450px) 100vw, 450px\" \/><\/p>\n<p>The screen is &#8220;Server Public Information&#8221; this is where you put the public IP of your web server. Previously I have entered the actual static IP of my server but the last time I left it as &#8220;0.0.0.0&#8221;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-3153\" src=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer02.jpg\" alt=\"\" width=\"500\" height=\"285\" srcset=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer02.jpg 500w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer02-150x86.jpg 150w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer02-300x171.jpg 300w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/p>\n<p>Then finally you get to summary screen. Check this over and click on &#8220;Apply&#8221;:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-3154\" src=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer03.jpg\" alt=\"\" width=\"600\" height=\"555\" srcset=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer03.jpg 600w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer03-150x139.jpg 150w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer03-300x278.jpg 300w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer03-324x300.jpg 324w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<p>When finished you should see:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-3155\" src=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer04.jpg\" alt=\"\" width=\"500\" height=\"462\" srcset=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer04.jpg 500w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer04-150x139.jpg 150w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer04-300x277.jpg 300w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer04-325x300.jpg 325w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/p>\n<p>At this point you will likely find that outside of your lan, on the Internet, people can get to your site but from the lan you can&#8217;t get to it. This is because the loopback policy is not working.<\/p>\n<p>You need to go to &#8220;Network | Routing&#8221; and you should find you have a new entry &#8220;DMZ Subnets&#8221;. You should click on the &#8220;Configure&#8221; button for this route:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-2606 size-full\" src=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/WALLWizardHTTP10.jpg\" alt=\"DMZ Route\" width=\"650\" height=\"214\" srcset=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/WALLWizardHTTP10.jpg 650w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/WALLWizardHTTP10-150x49.jpg 150w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/WALLWizardHTTP10-300x99.jpg 300w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/WALLWizardHTTP10-500x165.jpg 500w\" sizes=\"auto, (max-width: 650px) 100vw, 650px\" \/><\/p>\n<p>You should change this so it looks like:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-2607 size-full\" src=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/WALLWizardHTTP11.jpg\" alt=\"DMZ Route\" width=\"350\" height=\"450\" srcset=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/WALLWizardHTTP11.jpg 350w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/WALLWizardHTTP11-117x150.jpg 117w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/WALLWizardHTTP11-233x300.jpg 233w\" sizes=\"auto, (max-width: 350px) 100vw, 350px\" \/><\/p>\n<p>Naturally if you want this to be accessible via HTTPS you repeat but select HTTPS on the &#8220;Public Server Type&#8221; page.<\/p>\n<p>After getting this working I moved to a new Sonicwall. I am writing this part of the post some weeks after the event so I have forgotten the exact problem I had but I think it was around accessing from the LAN. None the less I am attaching some screen shots of the working system in case they are useful:<\/p>\n<p>&nbsp;<\/p>\n<figure id=\"attachment_3156\" aria-describedby=\"caption-attachment-3156\" style=\"width: 1200px\" class=\"wp-caption aligncenter\"><a  href=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer05.jpg\" class=\"thickbox no_icon\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-3156 size-full\" src=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer05.jpg\" alt=\"\" width=\"1200\" height=\"275\" srcset=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer05.jpg 1200w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer05-150x34.jpg 150w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer05-300x69.jpg 300w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer05-768x176.jpg 768w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer05-500x115.jpg 500w\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" \/><\/a><figcaption id=\"caption-attachment-3156\" class=\"wp-caption-text\">+Enlarge<\/figcaption><\/figure>\n<figure id=\"attachment_3157\" aria-describedby=\"caption-attachment-3157\" style=\"width: 1400px\" class=\"wp-caption aligncenter\"><a  href=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer06.jpg\" class=\"thickbox no_icon\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-3157 size-full\" src=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer06.jpg\" alt=\"\" width=\"1400\" height=\"464\" srcset=\"http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer06.jpg 1400w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer06-150x50.jpg 150w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer06-300x99.jpg 300w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer06-768x255.jpg 768w, http:\/\/www.zoyinc.com\/wp-content\/uploads\/2016\/08\/SonicWallPublicWebServer06-500x166.jpg 500w\" sizes=\"auto, (max-width: 1400px) 100vw, 1400px\" \/><\/a><figcaption id=\"caption-attachment-3157\" class=\"wp-caption-text\">+Enlarge<\/figcaption><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>\u00a0I have a SonicWALL TZ 205w sitting behind my fibre connection with my web server running on an ESXi server connected to the SonicWALL via a VLAN to isolate it from my LAN. This has proved to be a bit of a mission because I don&#8217;t have a modem between the SonicWALL and the ONT, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":2608,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[85,345],"tags":[347,352,359,357,356,346,353,358,355],"class_list":["post-2596","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-apache","category-sonicwall","tag-fibre","tag-firewall","tag-http","tag-loopback","tag-route","tag-sonicwall","tag-vlan","tag-web-server","tag-wizard"],"_links":{"self":[{"href":"http:\/\/www.zoyinc.com\/index.php?rest_route=\/wp\/v2\/posts\/2596","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.zoyinc.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.zoyinc.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.zoyinc.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/www.zoyinc.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2596"}],"version-history":[{"count":9,"href":"http:\/\/www.zoyinc.com\/index.php?rest_route=\/wp\/v2\/posts\/2596\/revisions"}],"predecessor-version":[{"id":3162,"href":"http:\/\/www.zoyinc.com\/index.php?rest_route=\/wp\/v2\/posts\/2596\/revisions\/3162"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.zoyinc.com\/index.php?rest_route=\/wp\/v2\/media\/2608"}],"wp:attachment":[{"href":"http:\/\/www.zoyinc.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2596"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.zoyinc.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2596"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.zoyinc.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2596"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}